Renewable traitor tracing
Abstract
A method to prevent the reuse of compromised keys in an emission coding system, characterized by: (a) incorporating a particular set of sequence keys assigned by a licensing agency to individual receivers; (b) assign a block of sequence keys (hereinafter SKB) by the licensing agency to at least one distributed protected file; (c) incremental cryptographic tests by individual receivers to determine (200) if a selected sequence key is compromised; (d1) If the selected sequence key is not compromised, then properly decode in response (202) the file and finalize the method; (d2) if the selected sequence key is compromised, then determine in response (204) if a subsequent sequence key of the set is available; (e1) if a subsequent sequence key is available, then select (206) that subsequent sequence key and return to step (c); and (e2) if a subsequent sequence key is not available, then the method terminates (208) without properly decoding the file.

Term
Term ended
Projected expiry passed 11 September 2026, 0 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
13 claims: 3 independent, 10 dependent
- 1ES 2 327 273 T3 REIVINDICACIONES 1. Un método para prevenir la reutilización de claves comprometidas en un sistema de codificación de emisión, caracterizado por:(a) incorporar un conjunto particular de claves de secuencia asignadas por una agencia de licenciamiento a receptores individuales;(b) asignar un bloque de claves de secuencia (en adelante SKB) por la agencia de licenciamiento al menos a un archivo protegido distribuido;(c) pruebas criptográficas incrementales por los receptores individuales para determinar (200) si una clave de secuencia seleccionada está comprometida;(d1) si la clave de secuencia seleccionada no está comprometida, entonces descodificar adecuadamente en respuesta (202) el archivo y finalizar el método;(d2) si la clave de secuencia seleccionada está comprometida, entonces determinar en respuesta (204) si se dispone de una clave de secuencia subsiguiente del conjunto;(e1) si está disponible una clave de secuencia subsiguiente, entonces seleccionar (206) esa clave de secuencia subsiguiente y volver a la etapa (c);y (e2) si no está disponible una clave de secuencia subsiguiente, entonces el método termina (208) sin descodificar apropiadamente el archivo.
- 2El método de la reivindicación 1, en el que las claves de secuencia seleccionan un conjunto particular de variaciones en el archivo.
- 3El método de la reivindicación 1, en el que el SKB se formula para revocar criptográficamente receptores particulares.
- 4El método de la reivindicación 1, en el que el conjunto incluye una lista con enlaces.
- 5El método de la reivindicación 1, en el que las pruebas comprenden además aplicar criptográficamente la clave de secuencia seleccionada y una clave de enlace si entonces está disponible al SKB para obtener un valor predeterminado que indique si la clave de secuencia seleccionada está comprometida.
- 6El método de la reivindicación 5, en el que, si la clave de secuencia seleccionada está comprometida, se genera una clave de enlace que conduzca a dicha clave de secuencia subsiguiente.
- 7Un producto de programa de ordenador para prevenir la reutilización de claves comprometidas en un sistema de codificación de emisión, que comprende un medio legible por ordenador que incorpore en el mismo de forma tangible un código ejecutable de ordenador, cuyo código se caracteriza por un primer código para incorporar un conjunto particular de claves de secuencia asignadas por una agencia de licenciamiento a receptores individuales;un segundo código para asignar un bloque de claves de secuencia (en adelante SKB) por la agencia de licenciamiento al menos a un archivo protegido distribuido;un tercer código para pruebas criptográficas incrementales por los receptores individuales para determinar (200) si una clave de secuencia está comprometida;un cuarto código para, si la clave de secuencia seleccionada no está comprometida, entonces descodificar apropiadamente en respuesta (202) el archivo y finalizar la operación del producto;un quinto código para, si la clave de secuencia seleccionada está comprometida, entonces determinar (204) en respuesta si está disponible una clave de secuencia subsiguiente;un sexto código para, si está disponible una clave de secuencia subsiguiente, entonces seleccionar (206) esa clave de secuencia subsiguiente y volver a las pruebas;un séptimo código para, si no está disponible una clave de secuencia subsiguiente, entonces finalizar (208) la operación del producto sin descodificar apropiadamente el archivo. ES 2 327 273 T3
- 8Un sistema para prevenir la reutilización de claves comprometidas en un sistema de codificación de emisión, caracterizado por medios para incorporar un conjunto particular de claves de secuencia asignadas por una agencia de licenciamiento a receptores individuales;medios para asignar un bloque de claves de secuencia (en adelante SKB) por la agencia de licenciamiento al menos a un archivo protegido distribuido;medios para pruebas criptográficas incrementales por los receptores individuales para determinar (200) si una clave de secuencia seleccionada está comprometida;medios para, si la clave de secuencia seleccionada no está comprometida, entonces descodificar adecuadamente en respuesta (202) el archivo y finalizar la operación;medios para, si la clave de secuencia seleccionada está comprometida, entonces determinar (204) en respuesta si está disponible una clave de secuencia subsiguiente del conjunto;medios para, si está disponible una clave de secuencia subsiguiente, entonces seleccionar (206) esa clave de secuencia subsiguiente y volver a las pruebas;medios para, si no está disponible una clave de secuencia subsiguiente, entonces finalizar (208) la operación sin descodificar adecuadamente el archivo.
- 9El sistema de la reivindicación 8, en el que las claves de secuencia seleccionan un conjunto particular de variaciones en el archivo.
- 10El sistema de la reivindicación 8, en el que el SKB se formula para revocar criptográficamente receptores particulares.
- 11El sistema de la reivindicación 8, en el que el conjunto incluye una lista con enlaces.
- 12El sistema de la reivindicación 8, en el que las pruebas comprenden además aplicar criptográficamente la clave de secuencia seleccionada y una clave de enlace si entonces está disponible al SKB para obtener un valor predeterminado que indique si la clave de secuencia seleccionada está comprometida.
- 13El sistema de la reivindicación 12, en el que si la clave de secuencia seleccionada está comprometida, se genera una clave de enlace que conduce a dicha clave de secuencia subsiguiente.
Independent claims13
92 paragraphs in 7 sections, as filed
ES 2 327 273 T3
DESCRIPTION
Renewable Traitor Tracking.
Field of application of the invention
This invention refers to the prevention of piracy of digital content in a broadcast encoding system, and more specifically, to the tracking of traitors who may be conspiring to redistribute said content and / or keys related to the decoding, and to revoke from renewable form compromised keys in order to prevent their further use in obtaining unauthorized access to the content.
Background of the invention
The widespread transition of data from analog to digital format has exacerbated problems related to unauthorized copying and redistribution of protected content. Flawless copies can be easily produced and distributed over the Internet or on physical media. This piracy is a major problem and expense for content providers; To solve this, consortia of industries such as Entity 4C (www.4centity.com) and AACSLA (www.aacsla.com>) have been formed. These groups are licensing agencies that provide content protection tools based on Content Protection for Recordable Media (CPRM) and Advanced Access Content System (AACS), respectively. CPRM is a technology developed and licensed by the 4C group, comprising IBM, Intel, Matsushita, and Toshiba, to enable consumers to make authorized copies of content for commercial entertainment in cases where the holder of the intellectual property rights for such content you have decided to protect it against unauthorized copying. AACS is a subsequent technology for the same purpose, under development by a group comprising IBM, Intel, Matsushita, Toshiba, Sony, Microsoft, Warner Brothers, and Disney.
CPRM and AACS protected files are encrypted with a key that is specific to a media identifier on their original storage media (such as a DVD or CD-ROM, etc.), so simply copying the content to another storage medium does not break protection. The CPRM also adds a Media Key Block (MKB) to the media. The MKB is a file that contains a large number of keys. Each individually compliant device is assigned a set of unique device keys that allow it to obtain the media key from the MKB, which is then combined with the media identifier and other values to obtain the keys used to decode the content. protected. Details of CPRM and AACS technology are described in PCT Patent Publication Nos. WO 02/06116, WO 02/060118, and in published US patent applications. numbers 2002-0106087, 2002-0114471, 2002-0104001 and 2004-11611 and are also available from 4C and AACS.
Fundamentally, AACS protection relies on the interaction between device keys and the tree-based media key block, which enables precise and unlimited cryptographic revocation of compromised devices without risk of collateral damage to innocent devices. Due to the inherent power of AACS system revocation, attackers may be able to forego building clones or breach devices and instead engage in attacks where they try to hide the underlying compromised device (or the underlying compromised devices). These attacks are more expensive and more legally risky for attackers, because the attacks require that they have an active server that serves either content keys or the content itself, on a case-by-case basis.
In addition to conventional CD-ROMs and DVDs, a new type of consumer home device has been enabled for digital content management through the advent of cheap, large-capacity hard drives. A movie rental box receives digital movies from some cheap data source, usually a broadcast source (either terrestrial or via satellite). Movies are stored on the hard drive, so that at any time the hard drive contains, for example, the 100 most popular movies on the rental market. The consumer selects and plays a given movie, and the movie rental box periodically calls a settlement center and reports the consumer's use of content for billing purposes; the box could also acquire new decoding keys during this call.
The most serious attack against these new devices is likely to be the so-called "anonymous" attack, in which a user or group of users buy rental movies from legitimate movie rental boxes that have been instrumented so that protected content and / or the decryption keys can be captured and redistributed, often over the Internet. This attack is the most pressing concern of movie studios investigating content protection technology. One solution to the problem is to watermark differently and encode each film for licensed movie rental box differently, such that if a film is pirated, the encoding and watermark information would uniquely identify the filmmaker. compromised box. Unfortunately, this solution is not feasible due to the excessive computing effort and transmission bandwidth required to prepare and transmit individualized films. The distribution system is only economical if the films can be distributed over broadcast channels, that is, where each receiver obtains substantially the same data at the same time.
ES 2 327 273 T3
The solution known in the art as "traitor tracking" could be used to solve the problem. In a particular example of this solution, an original version of each movie file is augmented before it is broadcast. Specifically, the file being output has actually had at least one critical file segment replaced by a set of variations. Each file segment variation is encoded differently, and preferably is also watermarked differently before encoding, although the entire file could also be watermarked. All variations in a segment are identical for display purposes, although digitally different. A particular receiver is preferably given the cryptographic key to decode only one of the variations in each segment. All legitimate receivers with valid decryption keys can play the content, but probably through different segment combinations. If the receiver has compromised and is used to illegally reissue either the keys or the segments themselves, it is possible to deduce which receiver or receivers have compromised.
The traitor tracking solution has not been widely used in practice to date, because previous implementations required unreasonable amounts of bandwidth in the broadcast, due to the number of segments or variations required. However, the published US patent application. N ° US 2004-11611, entitled "Method to track traitors and prevent piracy of digital content in a broadcast encryption system", describes a method of distributing protected content that combats piracy and allows the identification and revocation of compromised recipients in a broadcast coding system without excessive transmission bandwidth.
Document US 6839436 describes a method to prevent the reuse of compromised keys in a broadcast encryption system.
To summarize, whether it is with DVDs or with devices that are placed on top of the television or other means of distribution, a traitor tracking program has two basic stages: assigning the keys to the receiver devices to enable the tracking, and then identify traitors for revocation. Efficient traitor tracking technologies targeted at these two stages allow a licensing agency to more quickly identify traitors and prevent piracy by even larger groups of conspiring traitors.
However, what happens after a traitor has been identified and a particular compromised key or group of compromised keys has been revoked? The prior art is silent on the consequences of a single trace and revoke. What happens if a traitor repeats the attack and additional content is hacked, and / or a new key or set of new keys is compromised? A system is needed that allows innocent receiver devices to calculate a correct cryptographic response necessary to allow the content to be used, while preventing the traitor's devices from reaching that response.
Description of the invention
The invention employs sequence keys and a sequence key block (hereinafter SKB) to extend previous work on broadcast decoding and traitor tracking. Sequence keys are assigned by a licensing agency for individual playback devices preferably from an array of keys. The licensing agency also assigns SKB to be used on the prerecorded media, in a similar way to the media key blocks (MKB) used in the CPRM system. Any compliant device can process the SKB and get the correct decryption key and correctly access the content. In a preferred embodiment, successful SKB processing allows the device to properly use the set of variations assigned to it. When a traitor device has been identified and its sequence key set is to be revoked, a new SKB is formulated and distributed over the new media.
If a device has no compromised stream keys, it decrypts the protected content on the new media in a clear manner by calculating the correct decryption key, preferably for its assigned variations. If a device has a compromised sequence key, then that key is not used, but instead another sequence key from a group is selected (in a preferred embodiment, the next key is a linked list), and is used if she too has not committed too much. If it has also been compromised, then another available key is selected from the pool, and so on. Thus, innocent devices are given multiple opportunities to find an unrevoked sequence key in order to usefully decode the protected content. This concept provides the renewability of the sequence keys.
The formulation of the new SKB by the licensing agency ensures that all sequence keys from particular devices that have been identified as traitors are considered compromised when those devices try to reproduce content over new media. Thus, a treacherous device will have to go through all the sequence keys step by step without finding one that would usefully decode the protected content.
The invention could be used with broadcast decoding systems using distribution media that could include a computer network, satellite networks, cable networks, television broadcasts, and physical storage media. The files could comprise any kind of digital data stream, including (without limitation) text, audio, images, video, music, movies, multimedia presentations, operating systems, video games, software applications, and cryptographic keys.
ES 2 327 273 T3
Brief description of the drawings
Figure 1 is a prior art diagram of a modified distributed file.
Figure 2 is a flow chart of the basic operation of a preferred embodiment of the present invention.
Figure 3 is a diagram of a sequence key block (hereinafter SKB), according to a preferred embodiment of the present invention.
Figure 4 is a diagram of a "Nonce" record format (never repeating random value), in accordance with one embodiment of the present invention.
Figure 5 is a diagram of a record format for calculating variant data, in accordance with one embodiment of the present invention.
Figure 6 is a record format diagram for conditionally calculating variant data, in accordance with one embodiment of the present invention.
FIG. 7 is a diagram of a sequence key block record format end, in accordance with one embodiment of the present invention.
Detailed description of the invention
Referring now to FIG. 1, a prior art diagram of a modified or enlarged distributed file 100 is shown. This file is described in detail in published US patent application number US-2004-11611, entitled "Method for Tracking Traitors and Preventing Piracy of Digital Content in a Broadcast Encryption System." Augmented file 100 is the modified version of an original file that will actually be issued. Augmented file 100 includes sets of file variations that replace critical file segments. For example, a first critical file segment will be replaced with variations 102, 104, 106. and 108, while a second critical file segment will be replaced with variations 110, 112, 114, and 116, and so on.Each file segment variation is simply a copy of the corresponding particular critical file segment that has been marked with water differently and has been encoded differently. Each entire file has also typically been watermarked and modified in a broadcast coding system. Each file segment variation is identified by a text designation in this application (eg A, B, C, ... etc.) For clarity, but in practice binary numbers are generally used for that purpose.
The number of critical file segments and the number of file segment variations preferably employed depends on the properties of the file and its audience. For movies, a single critical file segment could be selected and have several hundred file segment variations; however, attackers could simply choose to omit that single critical file segment from a pirated copy of the file, in the hope that viewers will not find the glitch too annoying. A pirated movie with, say, 15 5-second critical scenes missing is probably going to be too annoying for any clairvoyant to be of any commercial value. Thus, illegally broadcast movies are either substantially disrupted or attackers must incorporate some of their file segment variations, making it easier to track down the traitor.
Each intended receiver in the broadcast requires variation selection information to choose a particular combination of file segment variations for each file. In relation to the setting of a movie rental box, each movie rental box must know, for each movie, which set of variations to introduce into the spaces where scenes existed in the original movie. The particular arrangement of modified file content and file segment variations within the augmented file 100 that have been shown is not critical, but simply intuitive.
The variations make it easy to track the traitor in a commercially viable way (i.e. low bandwidth overhead). If a pirated version of a file is found, for example on the Internet, the identity of a particular box (or particular boxes) of movie rentals that have been used to create the pirated version is of primary interest to the broadcaster and / or or content creator (for example, copyright owners). The broadcaster and / or content creator could institute legal proceedings against the culprit, and would surely want to refuse to send new decryption keys to the compromised boxes to prevent future theft. If different combinations of file segment variations are assigned to different boxes, an analysis of a hacked file can help determine which boxes have been used as part of an anonymous attack.
In the event that all file segment variations in a redistributed version of a file match the combination of file segment variations assigned to only a single movie rental box, prior art systems would normally identify that box. la as the source of the redistributed file. However, attackers are becoming increasingly sophisticated and may choose to employ a number of boxes to
ES 2 327 273 T3 produce a pirated version of a file by means of a conspiracy, where each box contributes to some information or content used to produce the illicit copy after enough of the said information or content has been accumulated.
Referring to Figure 2, a flow chart of the basic operation of a preferred embodiment of the present invention is shown. The formulation of the current SKB by the licensing agency ensures that all sequence keys on particular devices that have been identified as treacherous will be considered compromised when those devices attempt to reproduce new media content. Attackers would prefer to use already compromised sequence keys if they could, such that the licensing agency could not deduce new forensic information. Therefore, it is important that attackers can no longer use the compromised keys. The problem is that there are many thousands of devices that could have a single compromised key. Therefore, revocation of a single key is not practical.
On the other hand, since no two devices have many keys in common, even if the system has been heavily attacked and a significant fraction of the sequence keys have been compromised, all innocent devices will have many columns in which they have non-keys. committed. Thus, it is possible to revoke a set of compromised keys instead of a single key. The purpose of the sequence key block is to provide all innocent devices with a column that they can use to calculate the correct answer, while at the same time preventing treacherous devices (which have compromised keys in all columns) from getting the same one. answer. In an SKB there are actually many correct answers, one for each variation in content. However, for purposes of explanation, it is useful to imagine that a single SKB is producing a single response, called the output key. However, the invention is not limited to this case.
In step 200, the invention determines whether a selected sequence key is compromised. In a preferred embodiment, the sequence keys are examined one at a time, from the beginning of a linked list of sequence keys of a given receiver to its end, although the invention is not limited to this case. If a selected sequence key is not compromised, then the player is not considered treacherous and proceeds in step 202 to usefully decode the protected content as an authorized device would normally do, and the invention terminates. However, if the selected sequence key is compromised, then further processing is required to determine if the device is a traitor or is simply an innocent recipient who happens to have a sequence key in common with a traitor that has been identified and revoked. beforehand. If the device is known to be treacherous, all of its sequence keys will have to be revoked and thus are currently identifiable by the SKB as compromised. Thus, a treacherous receiver will proceed through all of its available sequence keys without finding a valid one.
Thus, in step 204 of a preferred embodiment, the invention checks whether the end of the sequence key list has been reached (more generally, the invention checks whether no additional sequence keys are available from the assigned set). If so, then at step 208 the receiver is treacherous according to the current KSB and the protected content has not been usefully decoded, and the invention terminates. However, if additional sequence keys are listed, then the invention proceeds to step 206, where in a preferred embodiment the selected sequence key is considered to be a link key and is used to achieve the next link key. sequence in the list with sequence key bindings. This next sequence key is selected as a candidate replacement for the compromised sequence key, and the invention returns to step 200 to verify if it is compromised. (Note that in the general case, the invention can select a candidate replacement for the committed sequence key from a set of sequence keys available in any order, even random). Therefore, an innocent recipient who happens to have a sequence key in common with an identified traitor is not immediately considered treacherous, but is instead allowed to use a valid renewal or replacement sequence key.
Sequence key sets are assigned to individual devices by the licensing agency from an array of keys. The licensing agency will generate sequence keys organized in a large matrix. The matrix preferably has 356 columns and no more than 65,536 rows. Each cell in the array is a different sequence key. A single receiving device has a key in each column. Thus, each device has 256 sequence keys in this example. In this respect, stream keys are somewhat analogous to CPRM media keys.
The licensing agency assigns the sequence key blocks to be used with protected files. Stream Key Blocks are similar to CPRM Media Key Blocks, but there are important differences, arising both from the use of different encryption languages (preferably AES rather than C2) and from considerations unique to specific attacks that might be employed. against the sequence key lists. However, unlike MKBs, Skbs are preferably not part of the fundamental cryptographic protection of the content. The fundamental protection of AACS is the media key. In a preferred embodiment of the present invention, the SKB simply allows different variants of the media key to be calculated by different devices.
Referring to Figure 3, a sequence key block diagram (SKB) is shown in accordance with a preferred embodiment of the present invention. The SKB begins with a first column 300, called the "unconditional" column. This column will have an encoding of the output key 302 (designated "K" in the figure) in each
ES 2 327 273 T3 uncommitted sequence key (to be precise, it is encoded in a key obtained from the sequence key, not from the sequence key itself). Devices that don't have compromised keys in that column immediately decode the output key, and you're done. Devices, both innocent and otherwise, that do have compromised keys in place preferably decode a key called a link key 304 that allows them to process an additional column in the SKB. To process the additional column, those devices need both the link key and its sequence key on that column. Therefore, subsequent columns are called "conditionals" because they can only be processed by the device if they have been given the necessary link key in a previous column.
Conditional columns are produced in the same way as the first column, that is, they will have an encoding of the output key on each uncommitted sequence key. Devices with a compromised key will get an additional link key 304 instead of the exit key. However, after some number of columns (depending on the actual number of compromised keys), the licensing agency will know that only compromised devices are getting the bind key, because all innocent devices would have found the exit key in this column or in a previous column. At this point, rather than encoding a link key, the agency simply encodes a 0 (item 306), and the SKB is complete.
How do devices know that they have a 304 link key versus 302 exit key? The short answer is that they don't know, at least not at first. Each conditional column preferably has a known data header 308 (eg, the hexademical value DEADBEEF is often used) encoded in link key 304 for that column. The device decodes the header 308 with the key it currently has. If the header 308 decodes correctly, the device knows that it has a link key 304 and processes the column. If it does not decode correctly, the device knows that it has either the output key 302 or a link key for an additional column. When you get to the end of the SKB, you know you must have a 302 exit key. Note that this device logic allows the licensing agency to send different populations of devices to different columns by having more than one link key output 304 from a single column. For example, in the figure, column (1) links both columns (2) and (5). This flexibility can help against certain types of attacks.
From the following attack scenario emerges an exclusive consideration for sequence key lists. Suppose a coalition of hackers has formed that includes one identified and revoked traitor, and at least one other recipient who has not been revoked. The first known traitor sequence key is used in a current SKB, resulting in a link key 304 because the sequence key is compromised. The invention then moves to the next column in the SKB, and tries to determine if it is dealing with an innocent recipient who has simply happened to have a compromised key in common with a traitor. However, instead of using the known traitor's next sequence key (which would lead to yet another link key 304 and eventually 0), the coalition now uses the other unrevoked receiver sequence key along with the link key. 304 from the previous column. In this attack and in variants related to it, there is the potential for the coalition to mislead the system and gain access to protected content in a way that would confuse subsequent tracking of all traitors. To guard against this scenario, the key matrix from which the SKBs have been generated is preferably subdivided into sub-populations small enough to allow deterministic identification of all traitors in a coalition comprising an identified revoked traitor and new ones. “Chaqueteros” who have not yet been identified and revoked by a given SKB. All traitor tracking schemes used in this scenario are within the scope of this invention. Similarly, SKB subdivision and population management are also employed against scenarios in which candidate sequence keys are not selected by proceeding through a set of sequence keys in any particular order.
Although the invention has previously been described as producing a single correct cryptographic response that allows access to protected content, in the broadest case, there is not just a single output key, but multiple output keys called variant data. The calculation of the media key variant data using sequence keys is described.
Each AACS compliant device capable of playing prerecorded content is given a set of secret sequence keys when manufactured. These keys are in addition to the device keys required by all AACS devices. Said sequence keys are provided by the licensing agency and are for use in processing the sequence key block. The result of the calculation is the variant data, which is then combined with the media keys from the media key block to generate the media key variant. Key sets can be either unique per device, or commonly used by multiple devices.
In a preferred embodiment, each device receives 256 64-bit sequence keys, referred to as K<sub>sJ</sub> (i = 0,1, ... 255). For each sequence key there is associated a column and row value, referred to as C<sub>sJ</sub> and R<sub>s</sub>_ (i = 0,1, ... n-1) respectively. Column and row values start at 0. For a given device, no two sequence keys will have the same associated column value (in other words, a device will have at most one sequence key per column). It is possible for a device to have some sequence keys with the same associated row values.
A device uses a sequence key K<sub>sJ</sub> along with the middle key K<sub>m</sub> to calculate the sequence key K<sub>ms</sub>_ as follows:
ES 2 327 273 T3
K .. = AES_G (Kmr K<sub>s</sub>_<sub>i</sub> !! 000000000000000016)
AES is the American encryption standard, a block cipher language adopted as an encryption standard by the US government. The AES is described in detail in the National Institute of Standards and Technology (hereinafter NIST), Advanced Coding Standard (hereinafter AES), FIPS Publication 197, November 26, 2001, and in the National Institute of Standards and Technology. , (NIST) Recommendation for Block Cipher Language Modes - Methods and Techniques, NIST Special Publication 800-38 / 2001 Edition. See also the AES Common Book, Advanced Access Content System: An Introduction and Common Cryptographic Elements.
AES_G is a one-way function defined using the AES cipher language. The result of the AES-based one-way function is calculated as:
AES_G (x<sub>1</sub>, x<sub>2</sub>) = AES_128D (x<sub>1</sub>, x<sub>2</sub>) XOR x<sub>2</sub>.
Where XOR is the bitwise exclusive-OR function AES_G is specified in the AES Common Book, section 2.1.3.
AES_ECBD is AES decoding function in electronic codebook mode (AES Electronic Codebook Decoding). In this mode, the cipher treats each block of 128-bit ciphertext as a word that will be decoded regardless of whoever came before or whoever came after, as if looking up in a codebook. When the ciphertext is used in this way, a change to a block of the ciphertext only affects the decoding of that block. Contrast this with AES in ciphertext block chaining mode, where each ciphertext block is combined with a computed value while the previous block is being decoded in order to decode it. When the cipher language is operated in the cipher block chaining mode, a change to any block of the ciphertext text affects the decoding of all subsequent blocks in the chain. AeS_ECBD (referred to as AES_128D (k, d) is specified in the AES common book, section 2.1.1
Therefore, stream keys play a similar role to device keys in CPRM, that is, the device does not use its stream key directly to decode, but instead combines it first with the media key as described. has previously shown. This means that a certain SKB is associated with a certain MKB (because the SKB depends on the media key for correct processing). A device preferably treats its sequence key as highly confidential, and its associated row values as confidential, as defined in the AACS licensing agreement.
The SKB is generated by the licensing agency and allows all compliant devices, each using its set of secret sequence keys and the media keys, to calculate the variant data, D<sub>v</sub>, which in turn allows them to calculate the media key variant. If a sequence key set is compromised in a way that threatens the integrity of the system, the updated SKB can be released causing a device with the compromised sequence key set to calculate invalid variant data. In this way, the compromised sequence keys are "revoked" by the new SKB.
An SKB is formatted as a sequence of contiguous Records. Each Record begins with a one-byte Record Type field, followed by a three-byte Record Length field. The record type field value indicates the type of the record, and the record length value indicates the number of bytes in the record, including the record type and record length fields themselves. The record type and record length fields are never encoded. Subsequent fields in a record could be coded, depending on the type of record.
Using its sequence keys, a device calculates D<sub>v</sub> processing the SKB records one by one, in order from first to last. Except where explicitly stated otherwise, a device must process each SKB record. The device should not make any assumptions about the length of the records and should instead use the value of the record length field to go from one record to the next. If a device finds a record with a record type field value that it does not recognize, it ignores that record and jumps to the next one. For some records, processing will result in the calculation of a Dv value. Processing subsequent records could update the value of D<sub>v</sub> that had been calculated previously. After SKB processing is complete, the device uses the most recently calculated Dv value as the final value for Dv.
If a device correctly processes an SKB using sequence keys that are revoked by that SKB, the D<sub>v </sub>resulting end will have the special value 0000000000000000<sub>16</sub>. This special value will never be a correct final value of D<sub>v</sub> SKB, and therefore can always be taken as an indication that the device sequence keys have been revoked. The behavior of the device in this situation is defined by the particular implementation. By way of example, a device could display a special diagnostic code, as useful information for a service technician.
The remainder of this application describes in detail a particular implementation of the present invention, including various formats that are likely to be followed by the AACS licensing agency. However, the present invention is not limited to this particular implementation.
ES 2 327 273 T3
Referring now to Figure 4, a Nonce (never repeating random value) record format is shown in accordance with one embodiment of the present invention. The Nonce number X is used in the calculation of variant data as described below. The Nonce record will always precede the variant data calculation record and the variant data conditional calculation records in the SKB, although it might not immediately precede them.
Referring now to Figure 5, a variant data calculation record format is shown in accordance with one embodiment of the present invention. A properly formatted SKB will have exactly one variant data calculation record. Devices should ignore any variant data calculation records found after the first in an SKB. The use of reserved fields is currently undefined, and they are ignored. The Generation field will contain 000116 for the first generation. The column field indicates the associated column value for the sequence key to use with this record, as described later. Bytes 20 and above contain encoded key data (possibly followed by some padding bytes at the end of the record, not shown in Figure 5). The first ten bytes of encoded key data correspond to sequence key row 0, and the next ten bytes correspond to sequence key row 1, and so on.
Before processing the registration, the device verifies that the following two conditions are true:
Generation = = 000001,<sub>6</sub><sup>Y</sup>
The device has a sequence key with an associated column value C<sub>d</sub>j = = column, or some i.
If either of these two conditions is false, the device ignores the rest of the record.
Otherwise, using the value i from the previous condition, the value X from the Nonce register, and r = R<sub>DJ</sub>, c = C<sub>DJ</sub>, the device calculates:
Dv = [AES (Kmsj, X XOR f (c, r))] ms<sub>b</sub>_<sub>8</sub>oXOR D<sub>what</sub>_<sub>x</sub>
Where K<sub>ms</sub>_<sub>i</sub> is the device yes<sup>esimo</sup> media stream key = value s and D<sub>ks</sub>_<sub>r</sub> is the 80-bit value starting at rx 10 byte offset within register = s encoded key data. F (c, r) represents the 128-bit value:
F (c, r) = 000016 !! c !! r !! 000000000000000016
Where c and r are left-padded to 16-bit lengths, prepending zero-valued bits to each as needed. The resulting Dv becomes the current variant data value.
It is not necessary for a first generation device to verify that the record length is sufficient to index into the encrypted key data. First generation devices ensure that the encrypted key data contains a value that corresponds to its associated device key row value.
Referring now to Figure 6, the format of conditionally calculating the data variant record is shown, in accordance with one embodiment of the present invention. A properly formatted SKB could have zero or more records of conditionally calculating media keys, bytes 4 through 19 of the record contain hard-coded conditional data (D<sub>EC</sub>). If successfully decoded, as described below, bytes 4 through 7 contain the value DEADBEEF<sub>16</sub>, bytes 8-9 contain the associated column value for the device key to use with this record, and bytes 10-11 contain a generation value of 000116 for the first generation. Bytes 20 and above contain double-encoded variant data (possibly followed by some padding bytes at the end of the record, not shown in Figure 6), The first ten bytes of double-encoded key data correspond to row 0 of keys sequence, the next ten bytes correspond to row 1 of sequence keys, and so on.
After finding a variant data calculation conditional record, the device first calculates its current media key variant, as follows:
Kmv = AES_G (Kmr Dv !! 000000000000000016)
Where Dv is your current variant data calculated from a previous variant data calculation record or a conditional variant data calculation record.
Using its current Kmv value, the device calculates the conditional data (Dc) as:
Dc = AES_EBCD (Kmv, Dce).
ES 2 327 273 T3
Before continuing to process the record, the device verifies that all of the following conditions are true: [Dc] msb_32 = DEADBEEF<sub>16</sub> Y
[Dc] 79:64 = 000116 <sup>Y</sup> the device has a sequence key with an associated value of column C<sub>DJ</sub> = = [D<sub>c</sub>] <sub>95:80</sub> for some i.
If any of these conditions are false, the device ignores the rest of the record.
Otherwise, using the value i from the previous condition, X from the Nonce register, the device s = Current data of variant D<sub>v</sub>, and r = R<sub>d</sub>,, c = C<sub>d</sub>,, the device calculates:
D<sub>v</sub> = [AES_G (K<sub>ms</sub>_<sub>i</sub>.X XOR f (c, r)) XOR D.). . . 8 XOR D<sub>k (fej</sub>
Where Dkde_r is the 80-bit value starting at a 10-byte rx offset within the double-encoded key data of the register, f (c, r) represents the 128-bit value:
f (c, r) = 000016 || c || 000016 || r || 000000000000000016 where c and r have been left padded to 16-bit lengths, prepending zero-valued bits to each as needed. The resulting Dv becomes the current variant data value. This register is always a multiple of 4 bytes: if necessary, padding bytes are added at the end.
Referring now to FIG. 7, an end of the sequence key block record format is shown, in accordance with one embodiment of the present invention. A properly formatted SKB contains a sequence key block record end. When a device encounters this record, it stops processing the SKB, using whatever Dv it has calculated up to that point as the final Dv for that SKB.
The bottom of the sequence key block record contains the licensing agency's signature on the sequence key block data up to, but not including, this record. Devices could ignore the signature data. However, if any device verifies the signatures and determines that the signature does not verify or has been bypassed, it must decline the use of the variant data. The length of this record is always a multiple of 4 bytes.
Regarding the calculation of the media key variant from the variant data, when the device has finished processing the SKB, and if it has not been revoked, it will have a valid 80-bit variant data Dv. The device calculates the media key variant from the variant data as follows:
Kmv = AES_G (Kmr D. || 000000000000000016)
Additionally, the low-order 10 bits of the variant data identify the variant number for the device to use in playing the content, from 0 to 1023. This number usually designates the particular title key file that the device should use. to decode the content, although the meaning and use of the variant number is format specific.
A general purpose computer is programmed in accordance with the steps of the invention herein. The invention can also be realized as an article of manufacture - a machine component - that is used by digital processing apparatus to execute current logic. This invention is carried out on a critical machine component that causes a digital processing apparatus to perform the steps of the method of the invention herein. The invention could be carried out by a computer program that is executed by a processor within a computer as a series of executable computer instructions. These instructions could reside, for example, in the RAM of a computer or on a hard disk or in an optical control of the computer, or the instructions could be stored in a DASD network, magnetic tape, electronic read-only memory, or other appropriate device for data storage.
Contents7
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
81 members in 15 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 20050230022 | United States of America | – | |
| 23002205 | United States of America | A | |
| 23002205 | United States of America | A | |
| 06793423230022 | – | – | – |
| US20050230022 | – | – | – |
Members81
| Document | Office | Kind | |
|---|---|---|---|
| JP2000031922A | Japan | A | |
| US6118873A | United States of America | A | |
| JP3195309B2 | Japan | B2 | |
| US2002104001A1 | United States of America | A1 | |
| WO02060116A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02060118A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2002228163A1 | Australia | A1 | |
| US2002106087A1 | United States of America | A1 | |
| US2002114471A1 | United States of America | A1 | |
| US2002133701A1 | United States of America | A1 | |
| WO02060118A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02060116A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2002147906A1 | United States of America | A1 | |
| US6609116B1 | United States of America | B1 | |
| EP1354443A2 | European Patent Office (EPO) | A2 | |
| EP1354444A2 | European Patent Office (EPO) | A2 | |
| KR20030085125A | Republic of Korea | A | |
| KR20030085126A | Republic of Korea | A | |
| US6650753B1 | United States of America | B1 | |
| CN1489847A | China | A | |
| US2004111611A1 | United States of America | A1 | |
| JP2004520743A | Japan | A | |
| US2004156503A1 | United States of America | A1 | |
| JP2004527937A | Japan | A | |
| TWI222302B | Taiwan Province of China | B | |
| CN1554163A | China | A | |
| US6832319B1 | United States of America | B1 | |
| US6883097B1 | United States of America | B1 | |
| HK1068513A1 | Hong Kong, China | A1 | |
| US6888944B2 | United States of America | B2 | |
| US2005195980A1 | United States of America | A1 | |
| US6947563B2 | United States of America | B2 | |
| KR100543630B1 | Republic of Korea | B1 | |
| US7007162B1 | United States of America | B1 | |
| US7010125B2 | United States of America | B2 | |
| KR100562982B1 | Republic of Korea | B1 | |
| US7039803B2 | United States of America | B2 | |
| TWI264208B | Taiwan Province of China | B | |
| CN1303777C | China | C | |
| US2007067244A1 | United States of America | A1 | |
| CN1310463C | China | C | |
| CA2623182A1 | Canada | A1 | |
| WO2007039411A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN1976277A | China | A | |
| US7380137B2 | United States of America | B2 | |
| EP1927213A1 | European Patent Office (EPO) | A1 | |
| US2008181410A1 | United States of America | A1 | |
| US2008192939A1 | United States of America | A1 | |
| CN101268652A | China | A | |
| AT411665T | Austria | T | |
| ATE411665T1 | Austria | T1 | |
| EP1354444B1 | European Patent Office (EPO) | B1 | |
| IL190211D0 | Israel | D0 | |
| DE60229354D1 | Germany | D1 | |
| JP2009509371A | Japan | A | |
| US7505593B2 | United States of America | B2 | |
| US7523307B2 | United States of America | B2 | |
| EP1927213B1 | European Patent Office (EPO) | B1 | |
| AT432560T | Austria | T | |
| ATE432560T1 | Austria | T1 | |
| DE602006007019D1 | Germany | D1 | |
| EP1354443B1 | European Patent Office (EPO) | B1 | |
| AT445269T | Austria | T | |
| ATE445269T1 | Austria | T1 | |
| ES2327273T3This record | Spain | T3 | |
| DE60233929D1 | Germany | D1 | |
| ES2334109T3 | Spain | T3 | |
| US7698551B2 | United States of America | B2 | |
| US7770030B2 | United States of America | B2 | |
| CN1976277B | China | B | |
| US7925025B2 | United States of America | B2 | |
| BRPI0617419A2 | Brazil | A2 | |
| CN101268652B | China | B | |
| IL190211A | Israel | A | |
| EP1354443B2 | European Patent Office (EPO) | B2 | |
| ES2334109T5 | Spain | T5 | |
| CA2623182C | Canada | C | |
| US9520993B2 | United States of America | B2 | |
| US2017063558A1 | United States of America | A1 | |
| BRPI0617419B1 | Brazil | B1 | |
| US11108569B2 | United States of America | B2 |
Numbers
- Publication
- 2327273
- Publication, DOCDB
- 2327273
- Publication, EPODOC
- ES2327273T
- Application
- 6793423
- Application, DOCDB
- 06793423
- Application, EPODOC
- ES20060793423T
Titles2
- Spanish
- RASTREO RENOVABLE DE TRAIDORES.
- English
- RENEWABLE TRAITORS TRACKING.
Classification
- CPC, 7
- H04L9/083
- H04L9/3268
- H04L9/0891
- H04L2209/601
- H04L2209/606
- H04L9/3247
- H04L63/061
- IPC, 1
- H04L9 08